CVE-2018-1567: IBM WebSphere Application Server

Critical severity, CVSS 9.8. EPSS: 3.8% chance of exploitation in the next 30 days.

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a serialized object from untrusted sources. IBM X-Force ID: 143024.

Affected products

  • IBM WebSphere Application Server: from 7.0.0.0, up to and including 7.0.0.45; from 8.0.0.0, up to and including 8.0.0.15; from 8.5.0.0, up to and including 8.5.5.14; from 9.0.0.0, up to and including 9.0.0.9

Published 2018-09-07. Last modified 2026-06-17.